Content Locker for Email Capture Security & Risk Analysis

wordpress.org/plugins/content-locker-for-email-capture

A powerful WordPress plugin that locks premium content behind an email subscription form.

0 active installs v1.0.0 PHP 7.2+ WP 6.2+ Updated Sep 12, 2025
content-lockercontent-protectionemail-capturelead-generation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Content Locker for Email Capture Safe to Use in 2026?

Generally Safe

Score 100/100

Content Locker for Email Capture has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "content-locker-for-email-capture" plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Crucially, all SQL queries are prepared, and all output is properly escaped, mitigating common web application vulnerabilities like SQL injection and cross-site scripting (XSS). The plugin also implements a nonce check, a vital component for AJAX security. The vulnerability history being clean with zero known CVEs further bolsters confidence in its current security.

However, a notable area for improvement is the lack of capability checks for its entry points. While the static analysis indicates that all entry points have either AJAX handlers or shortcodes, only one nonce check is present, and critically, zero capability checks are evident. This means that certain actions might be accessible to users without the necessary WordPress permissions, potentially allowing unauthorized access or manipulation if an attacker can bypass or exploit the nonce. The plugin's small attack surface is a positive, but the absence of explicit capability checks is a potential weakness that could be exploited in certain scenarios.

In conclusion, this plugin demonstrates good development practices in several key areas, particularly regarding data handling and output sanitization. The clean vulnerability history is a significant strength. The primary concern lies in the absence of capability checks for its entry points, which represents a potential avenue for privilege escalation or unauthorized actions. While the current version appears secure against common exploitation methods, implementing robust capability checks would significantly harden its security posture.

Key Concerns

  • Missing capability checks for entry points
Vulnerabilities
None known

Content Locker for Email Capture Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Content Locker for Email Capture Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
5 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped5 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<content-locker-for-email-capture> (content-locker-for-email-capture.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Content Locker for Email Capture Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_clec_submit_emailcontent-locker-for-email-capture.php:108
noprivwp_ajax_clec_submit_emailcontent-locker-for-email-capture.php:109

Shortcodes 1

[clec_content_lock] content-locker-for-email-capture.php:69
WordPress Hooks 2
actionwp_enqueue_scriptscontent-locker-for-email-capture.php:80
actionadmin_menucontent-locker-for-email-capture.php:124
Maintenance & Trust

Content Locker for Email Capture Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 12, 2025
PHP min version7.2
Downloads269

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Content Locker for Email Capture Developer Profile

WP Shopify Expert

3 plugins · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Content Locker for Email Capture

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/content-locker-for-email-capture/css/style.css/wp-content/plugins/content-locker-for-email-capture/js/script.js
Script Paths
js/script.js
Version Parameters
content-locker-for-email-capture/css/style.css?ver=content-locker-for-email-capture/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
content-locker-wrapperlocked-contentemail-capture-formclec-admin-content
Data Attributes
id="clec-email-form"id="clec-email"id="clec-message"
JS Globals
clec_ajaxclec_ajax.ajax_urlclec_ajax.nonce
Shortcode Output
[clec_content_lock][clec_content_lock]Your content here[/clec_content_lock]
FAQ

Frequently Asked Questions about Content Locker for Email Capture